Home All services
Start a project → Call Now

Risk management as a service (RMaaS) for boards

Show your board which risks moved since it last looked — and why.

An annual risk assessment shows your board where risk stood on one day. On a retainer, we keep your risk register current: the running list of your cyber risks, each with an owner. From it your board gets a regular cyber posture pack, with colour-coded heat maps scored the same way each time, your vendors sorted into risk tiers, and the gaps your executives found when they rehearsed an incident.

  • Each pack scored the same way as the last
  • 6-month minimum, 12-month default term
  • We reply within one working day.
  • NIST CSF 2.0, GV.RM-06
  • NIST CSF 2.0, GV.SC-07
  • CISA Tabletop Exercise Packages
Illustration: two glass panels showing the same grid of risk tiles, with more tiles lit and ticked on the second panel and one tile in amber, an arrow pointing from the first to the second, and a report folder in front

In brief

What it is
Cyber risk management on a retainer instead of a one-off project, so your list of risks stays current between board meetings.
Why it matters
A one-off report shows where risk stood on one day. Compare each pack with the last one, scored the same way, and your board sees which risks grew, which shrank and why.
What you get
A living risk register, board-ready cyber posture packs with heat maps, vendor risk tiers, and executive tabletop exercises for ransomware and data breach scenarios.

What the retainer covers

A risk register kept live, and the board reports drawn from it.

RMaaS is one of our managed security and compliance services. It helps your leadership make risk decisions it can explain to a board, an auditor or a customer.

A living risk register

Your list of cyber risks, kept current for the whole term. Each risk has an owner, a treatment and its current state. Your vendors' risks sit in the same register, next to the business risks they affect.

A board-ready posture pack

The register condensed for directors, with heat maps: colour-coded grids that show where risk sits. Every risk that moved up or down a rating band comes with a reason. On the enterprise tier (around 40 to 50 dedicated hours a month), we also report to your board directly.

Executive tabletop exercises

Your executives rehearse a ransomware or data breach scenario taken from your own register. You get the gaps it exposes, such as a decision nobody in the room had the authority to make, each logged in the register with an owner.

Want a security executive to keep the register and present it to your board? See vCISO services. Need audit evidence kept current too? GRC as a service runs the register and audit readiness as one program, and compliance as a service covers the evidence alone.

Snapshot or record

See what moved since the last pack, not just where risk stands today.

A heat map is a picture of a single day. On its own it tells your board little. Next to the previous one, scored the same way, it shows what moved. Change the scoring method and a risk turns red with nothing behind it. Here are the same board questions, put to each kind of report.

Our reading of each report type. It assumes the standard risk method that the NIST Cybersecurity Framework (CSF) 2.0 describes at GV.RM-06.
What the board asksAnnual assessmentRegister on retainer
Which risks moved since we last looked?It cannot say; it has one dateEach move and the event behind it
Which accepted risks need a new decision?Whatever the next assessment findsThose past their review date, or hit by an event that calls for a new decision
Did the fixes we paid for lower the rating?Target dates in a treatment planThe rating each risk still carries after a fix (its residual rating)
Which vendor could hurt us most now?The vendor list on the day of the assessmentCurrent tiers and changes since the last pack
Can we show oversight to an auditor?One dated reportDated packs and the decisions in them
What NIST CSF 2.0 says about a standard risk method (GV.RM-06)

At GV.RM-06, NIST's Cybersecurity Framework (CSF) 2.0 describes a standard method for calculating, documenting, categorizing and prioritizing cybersecurity risks. The table above assumes that method is in place, so each pack is scored the same way as the one before it.

To see where you stand against the whole framework, see NIST CSF 2.0.

For what makes a register useful, and the frameworks behind its scores, see our risk management page.

Vendor risk tiers

Vendor risk tiers that keep pace with the relationship.

See which suppliers sit behind the risks your board already watches, for as long as you work with them.

An onboarding questionnaire checks a vendor once, at the start. NIST's CSF 2.0 outcome GV.SC-07 describes something longer: supplier and third-party risks recorded, prioritized, assessed, responded to and monitored for the life of the relationship.

On the retainer, we sort your vendors into tiers by risk and evaluate the supply chain behind them, meaning their own suppliers.

What a vendor entry carries into the pack

  • Its tier. The vendor's current tier, and one plain line on why.
  • Linked risks. The register risks that depend on it.
  • Contract gaps. Gaps still open, each with a named owner.
  • Its suppliers. Suppliers further down its chain that the evaluation flagged.
  • Tabletop status. Whether a tabletop has tested what happens if it fails.

Judging one vendor by the access it holds is covered on our third-party risk management page.

Executive tabletops

Rehearse ransomware and data breach decisions before they are real.

A tabletop exercise is a guided discussion: your executives talk through an incident scenario and make the calls it forces. It tests decisions, not technology. Each exercise starts in the register and ends back in it.

  1. Start from the register

    The scenario comes from risks the pack already ranks high, such as ransomware on a core system or theft of customer personal data.

  2. Let a critical vendor start it

    CISA, the US Cybersecurity and Infrastructure Security Agency, publishes a vendor supply chain compromise tabletop manual dated August 2024. A ransomware or breach scenario can begin at a critical vendor, which tests your vendor tiers as well as your executives.

  3. Put the calls to your executives

    Each turn of the scenario forces a decision executives would face in a real incident. If nobody in the room holds the authority to make one, that missing authority is itself a gap.

  4. Write the gaps into the register

    Each gap the exercise exposes becomes a register entry with an owner. If your retainer includes incident escalation coordination, as the enterprise tier does, the escalation path you rehearse is the one we coordinate in a real incident. The tabletop is one of our Blue Team exercises; response teams rehearse the technical side in incident response drills and detection checks.

Vetting providers

Questions to put to any RMaaS provider.

Test each proposal against what your board will actually read.

  • A sample pack. Ask for a sample posture pack, and check that it asks the board to decide something.
  • Who signs. Confirm that only your leadership can accept a risk. A provider may recommend but should not sign.
  • Your access. Ask whether your own staff can read and update the register between packs.
  • Board risks and management gaps. Ask how the pack separates risks the board must own from gaps management can close.
  • Promises. Treat a promised percentage of risk removed as a warning sign.
  • What sits outside. Ask what the retainer leaves out, such as legal advice.

The limits of our own retainer. We recommend, and only your leadership accepts a risk. We do not promise a percentage of risk removed. SecWiz is not a law firm, so legal advice is not part of the retainer.

FAQ

What buyers ask before retaining a risk service.

Board packs, vendors, tabletops and terms. For anything else, ask us directly.

Risk Management as a Service (RMaaS) is cyber risk management bought as a retainer rather than a one-off project. At SecWiz it covers a living risk register, board-ready cyber posture packs with risk heat maps, vendor risk tiering and supply-chain evaluation, and executive tabletop exercises for ransomware and data breach scenarios.

An annual assessment records risk as it stood while the assessor was looking, then stays fixed. RMaaS keeps the register current through the retainer, so each board pack reads against the one before. The board sees direction: which risks grew, which shrank after treatment, and which decisions came due. One report shows only position.

A posture pack is the risk register condensed for directors. It holds heat maps scored with the same method as the last pack, a reason for every risk that changed band, accepted risks due for review, current vendor tiers and open tabletop gaps. On the enterprise tier, the retainer also includes direct board-level reporting.

Yes. Active third-party risk management is part of the retainer. Vendors are sorted into risk tiers, supply-chain evaluation looks past them to their own suppliers, and the results sit in the same register as internal risks, so the board pack shows a vendor's weakness beside the business risk it affects.

It tests decisions, not technology. Executives work through a ransomware or data breach scenario drawn from their own risk register and make the calls a real incident forces: whether to take a system offline, what to tell customers and regulators, who has the authority to decide, and who speaks for the company while it happens.

SecWiz sets a 6-month minimum term and a 12-month default, because remediating risk takes time to show results. Continuous automated compliance monitoring comes with a mid-market / growth retainer of around 20 to 25 committed fractional executive hours a month. On an enterprise retainer, direct board-level reporting and incident escalation coordination are part of around 40 to 50 dedicated hours a month.

Let's talk

Bring the last risk report your board saw.

Send it however old it is, or tell us nobody has produced one. The conversation starts from that report. We reply within one working day.